The malware was not in the app. It was in .git/hooks.
My first job hunt taught me to inspect the repo before trusting the task
I am currently looking for my first job So when a recruiter messaged me on LinkedIn and sent over a take-home repository, I tre